Internet of Medical Things Security Frameworks for Risk Assessment and Management: A Scoping Review
DOI: https://doi.org/10.2147/jmdh.s459987
2024-05-14
Journal of Multidisciplinary Healthcare
Abstract:Katerina Svandova, &ast Zdenek Smutny &ast Faculty of Informatics and Statistics, Prague University of Economics and Business, Prague, Czech Republic &astThese authors contributed equally to this work Correspondence: Zdenek Smutny, Faculty of Informatics and Statistics, Prague University of Economics and Business, W. Churchill Sq. 1938/4, 130 67 Prague 3, Prague, Czech Republic, Email Background: The massive expansion of the Internet of medical things (IoMT) technology brings many opportunities for improving healthcare. At the same time, their use increases security risks, brings security and privacy concerns, and threatens the functioning of healthcare facilities or healthcare provision. Purpose: This scoping review aims to identify progress in designing risk assessment and management frameworks for IoMT security. The frameworks found are divided into two groups according to whether frameworks address the technological design of risk management or assess technological measures to ensure the security of the IoMT environment. Furthermore, the article intends to find out whether frameworks also include an assessment of organisational measures related to IoMT security. Methods: This review was prepared using PRISMA ScR guidelines. Relevant studies were searched in the citation databases Web of Science and Scopus. The search was limited to articles published in English between 2018 and 17 September 2023. The initial search yielded 1341 articles, of which 44 (3.3%) were included in the scoping review. A qualitative content analysis focused on selected security perspectives and progress in the given area was carried out. Results: Thirty-two articles describe the design of risk assessment and management frameworks. Twelve articles describe the design of frameworks for assessing the security of IoMT devices and possibly offer a comparison of different IoMT alternatives. A description of the included articles was prepared from the selected security perspectives. Conclusion: The review shows the need to create comprehensive or holistic frameworks for operational security and privacy risk management at all layers of the IoMT architecture. It includes the design of specific technological solutions and frameworks for continuously assessing the overall level of information security and privacy of the IoMT environment. Unfortunately, none of the found frameworks offer an assessment of organizational measures even though the importance of the organization measures was highlighted in articles. Another area of interest for researchers could be the design of a general risk management database for IoMT, which would include potential IoMT-related risks connected to a particular device. Keywords: cybersecurity, healthcare, information systems, IoMT, internet of things, IoT, threat, sensors Medical devices, equipment, sensors and applications that use wireless networks and the Internet to connect are referred to as the Internet of medical things (IoMT), 1 formerly also referred to as the medical Internet of things. 2 Their rapid spread in recent years has enabled the collection of patient health data, patient monitoring, automation of certain processes and subsequent analysis of the data collected. Examples include smart watches and wristbands, sensor-equipped medical devices such as glucose meters, electrocardiogram devices, blood pressure monitors, as well as sensors that monitor patients remotely, enabling monitoring of the patient's vital signs, and possibly also detecting falls. Healthcare systems face increasing numbers of patients and associated challenges. 3 The use of IoMT has the potential to make diagnosis more accurate, enable earlier detection of disease, improve patients' quality of life and reduce healthcare costs. It also means increasing the ability to incorporate advanced technologies, such as artificial intelligence, to support correct diagnosis. 4 The IoMT is a subset of devices connected to the environment via the Internet, the so-called Internet of things (IoT). Typically, these devices have sensors, low power consumption, small memory capacity and data processing capability. Data and services are provided to users remotely. 5 This is a diverse technology found in healthcare facilities that share a common way of connecting to the outside world via the Internet. This poses an increased security risk. At the same time, their use and operation involve collecting and sharing sensitive data about individual patients. A potential cyberattack threatens not only the specific device and its functioning but also, due to the connection to other hospital systems, endangering the health and life of patients. Karie et al -Abstract Truncated-
health care sciences & services